Sign inSign up
PHP

dhi.io/php

PHP 8.2.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

8.2-alpine-fips-dev, 8.2-alpine3.24-fips-dev, 8.2.34-alpine-fips-dev, 8.2.34-alpine3.24-fips-dev

Index digest:

sha256:daad0879dc4faebdd2c1f149f7efe6cf384e5c847ca0f11463fc182386aaf267

Manifest digest:

sha256:774eff5e498316c7ee671008b2990879da1f19eaae5b74fd3322a4163580e861

Size

132.84 MB

Last pushed

1 day ago

Vulnerabilities

0
0
2
0
0

Support

Active until Dec 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.2-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.2-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:6224370fe9af68c5bd83c2187909483828d0715ddbdea165e734a8682a80d446
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:51e86d0d44988378d79e46f36c83db0930b424e61f72399e46954e556e04fe54
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/php@sha256:71535d19b40ddc3e31ee7e14463f44abd1f3166fed2300d1899f1c93f66894a9
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:15224cab41e3e386087591072f05f27b116e16859b1364b9e56e6162fdd74747
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/php@sha256:dcf049dcc77c698db25bf6a078fd62ca004369e20d96ddb026d008dee95bb234
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:628c03cd7af0ec8563fd179f6376165490664306ac471d563cf062a6c6f1e20c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:220e907c400dad58b1de110ee9d861d65b7410fe6f3e11fb57f30b3472b89797
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:22cc1339b81e1fd03b7c691bab09c25892b8a46bab5aa22a4daa643172104294
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:58d187a48561c163977d954584fbcae1b8bb0fec275616501520f2cd1d6af4cd
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:8c504afc0f4db73f44d5733798aca1c15a94ce69f37a05cda53eae469cdcb2a7
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:195fec58175faf747809468a4d0df1da383f2f13862ac0cf07356e2d0f7324e4
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:aa8a24286d4f4f3759081434c54d0a09fc1c8ec3b073d64a98fc996927c9222a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:5d5c795b23e77f36f151b2625a0cb94148337cf0a01f8c3c5eb7f81300638e45
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:c024efdb94d357a057c66db4647d225bd935c1f359b35c53267b3788ffc3adab
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:e4b4129366401d24c58b18f31e55d9159b33d6b620550757f937a5990c61dab1
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:60c2fe83de9842611455cd26a3f9a0972f9f62fff8fd836ae04fabb4c5f3290b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:a7dcf5d4fa8e0def8570b908754065fdd6334d889694bd756cc17f14b818a95a